#56 - Leah Culver of Breaker and Tom Sparks of YC Answer Your Questions About Security and Podcasting artwork

#56 - Leah Culver of Breaker and Tom Sparks of YC Answer Your Questions About Security and Podcasting

Y Combinator Startup Podcast

January 5, 2018

Leah Culver is cofounder and CTO of Breaker, which is a social podcast listening and discovery app. They went through YC in the Winter 2017 batch. Leah’s also an author of both the OAuth and oEmbed API specifications.Tom Sparks is an engineer on the YC Software team.
Speakers: Craig Cannon, Tom Sparks, Leah Culver
**Craig Cannon** (0:00)
Hey, how's it going? This is Craig Cannon, and you're listening to Y Combinator's podcast.
Today's episode is with Leah Culver and Tom Sparks. Leah is the co-founder and CTO of Breaker, which is a social podcast listening and discovery app. Breaker went through YC in the winter 2017 batch. And Leah is also an author of both the OAuth and Oembed API specifications. Tom's an engineer here on the YC software team, and he also co-founded Cryptoseal, which went through YC in the summer 2011 batch. They were later acquired by CloudFlare in 2014 So the first part of this episode is about security, and the second part is about podcasting.
We answered a ton of questions from Twitter, so hopefully we got to yours. All right, here we go. All right, so how about we start with some questions from Twitter? I actually think this one might have been on Facebook. So Brady Simpson asked, how do we deal with the ever increasing pressure from governments trying to get into devices? Tom, do you have an opinion on this one?

**Tom Sparks** (0:57)
So I think one of the most important things to think about is that some of this is just legislation based.
However, some vendors do actually care about the privacy and security of their users. Apple's been pretty good about it. Microsoft has actually done a lot of work for this. Previously, when BlackBerry was still a thing, they were basically number one. But right now, Apple's pretty much the most consumer friendly in terms of security for just your personal devices. They give you a lot of options. They do a lot of stuff behind the scenes to make it really easy. Your passcode is actually backed by some really, really cool stuff. Your fingerprint reader on your phone is pretty simple. It works pretty much all the time.
So that's easy security stuff. The government trying to subpoena the information from your devices is a lot bigger can of worms. And it kind of goes back to the Constitution essentially, like Fourth Amendment, Fifth Amendment stuff. So search and seizure is really kind of up in the air with electronic devices. This kind of goes all the way back to the 1960s in terms of personal privacy. In the 60s, the government came up with something called Echelon, I believe.
And that was basically trying to get data to spy on spies. In the 90s, it was Clinton trying to do stuff to catch more spies, basically. And with email and stuff becoming more and more prevalent, they just put in this giant apparatus to do surveillance on the American population.
So vendors, when they tackled this, kind of have to go, well, what can we do without taking off the government? Apple's done a good job of basically saying, no, we're not going to give you the keys to things. If you want to get into somebody's phone, you're going to have to basically get around the protections we've put in because we don't want to make something that's intentionally insecure. And they've done pretty well with that. They've gotten some flak from some people.

**Craig Cannon** (3:14)
So as a lay person, what precautions are you taking with your own data?

**Tom Sparks** (3:19)
I think for the most part, as long as you use the key code and any sort of biometric authentication on your devices, you're in a good spot. If you don't do any of that, you're just kind of in the wind.
The government has pretty deep ability to surveil you. So your phone is probably not really going to be the vector they go after the most unless you're sending encrypted messages and stuff. If you've got Signal, they probably want to see what you're doing. But if they can subpoena you and you don't have good protection on your phone, they're going to see what's there. They can't make Apple decrypt what you've got. If you've got an Android phone, you're much less well off. So it's really just legislation and using good technology.
I believe the Pixel 8, or what is it? The new Samsung phone has some pretty neat stuff built into it that's got good security.

**Craig Cannon** (4:32)
What about you, Leah? Do you do anything in particular?

**Leah Culver** (4:35)
I'm actually, so I have an iPhone and I have some little paranoia things. Like I know how to turn off the phone, so if I was like panicked. So I actually just got the iPhone X, so I have the facial recognition.
But I always tend to get the latest iPhone, so I had the Touch ID as well. And the interesting thing is I think it's much easier for law enforcement to access your phone via Touch ID, like you were saying, through Touch ID or facial recognition. But the nice thing Apple does is if you have three failed attempts, or if you shut off your phone, you have to re-enter your passcode, and that's much harder for them to access.

50 more minutes of transcript below

Feed this to your agent

Try it now — copy, paste, done:

curl -H "x-api-key: pt_demo" \
  https://spoken.md/transcripts/1000651996090

Works with Claude, ChatGPT, Cursor, and any agent that makes HTTP calls.

From $0.10 per transcript. No subscription. Credits never expire.

Using your own key:

curl -H "x-api-key: YOUR_KEY" \
  https://spoken.md/transcripts/1000399138398